Law / United Arab Emirates

ADGM Data Protection Regulations, breach notification

ADGM Data Protection Regulations 2021, personal data breach notification provisions

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 14 February 2021.

A breach notification rule binding private bodies.

As of 29 August 2026.

What it requires

  • An app that is a controller or processor established in or targeting the ADGM free zone and that suffers a personal data breach must notify the Commissioner of Data Protection without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to pose a risk to individuals' rights.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The ADGM Data Protection Regulations set an explicit 72-hour breach-notification rule to the Commissioner of Data Protection, language read verbatim and drawn from the same family as General Data Protection Regulation (GDPR) Art. 33, unless the breach is unlikely to pose a risk to individuals' rights.

This is the only one of the UAE's three regimes where a specific notification window was confirmed; the federal PDPL defers its timeline to unconfirmed Executive Regulations, and the DIFC Law's own breach-notification timeline (Part 7) was not individually pulled.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

Read the law

official consolidated Regulations text (PDF), ADGM rulebook

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app